logo

PoC Exploit Publicly Disclosed: Windows ‘libarchive’ Flaw Leaks NetNTLMv2 Hashes

ID: 2f0cd94a-159d-5053-8c20-9332968c42ed

STIX ID: report--2f0cd94a-159d-5053-8c20-9332968c42ed

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-03-20

Date Updated: 2026-04-23

Author: Ddos

...
...

Security researchers disclosed CVE-2025-59284 in Windows' libarchive handling: a specially crafted tar with hardlinks can force the OS to resolve a UNC path during archive extraction or file open, causing NetNTLMv2 authentication requests to be sent to attacker-controlled servers and leaking hashes; a public PoC exists and Microsoft’s patch currently displays a warning dialog that may not prevent exploitation if users accept it.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.